CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2025-14174Hoch8.8
Out-of-Bounds-Speicherzugriff in ANGLE in Google Chrome auf Mac vor 143.0.7499.110 ermöglichte es einem Remote-Angreifer, über eine präparierte HTML-Seite einen Out-of-Bounds-Speicherzugriff durchzuführen. (Chromium-Sicherheitsschweregrad: Hoch)
- CVE-2025-8110Hoch8.8
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
- CVE-2025-62221Hoch7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-59718Kritisch9.8
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
- CVE-2025-48633Mittel5.5
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-48572Hoch7.8
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-34291Hoch8.8
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
- CVE-2025-66644Hoch7.2
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- CVE-2025-55182Kritisch10.0
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
- CVE-2025-58487Mittel4.0
Unsachgemäße Autorisierung in Samsung Account vor Version 15.5.01.1 ermöglicht einem lokalen Angreifer, beliebige Aktivitäten mit Samsung Account-Berechtigung zu starten.
- CVE-2025-58486Mittel4.0
Unsachgemäße Eingabevalidierung in Samsung Account vor Version 15.5.01.1 ermöglicht es einem lokalen Angreifer, ein beliebiges Skript auszuführen.
- CVE-2025-62593Hoch8.8
Ray ist eine KI-Computing-Engine. Vor Version 2.52.0 können Entwickler, die Ray als Entwicklungstool verwenden, über eine kritische RCE-Schwachstelle ausgenutzt werden, die über Firefox und Safari ausnutzbar ist. Diese Schwachstelle beruht auf einem unzureichenden Schutz vor browserbasierten Angriffen, da die aktuelle Abwehr den User-Agent-Header, der mit der Zeichenkette "Mozilla" beginnt, als Abwehrmechanismus verwendet. Diese Abwehr ist unzureichend, da die Fetch-Spezifikation das Ändern des User-Agent-Headers erlaubt. In Kombination mit einem DNS-Rebinding-Angriff auf den Browser ist diese Schwachstelle gegen einen Entwickler, der Ray ausführt und versehentlich eine bösartige Website besucht oder dem eine bösartige Werbung (Malvertising) angezeigt wird, ausnutzbar. Dieses Problem wurde in Version 2.52.0 behoben.
- CVE-2025-58360Hoch8.2
GeoServer ist ein Open-Source-Server, der es Benutzern ermöglicht, Geodaten gemeinsam zu nutzen und zu bearbeiten. Von Version 2.26.0 bis vor 2.26.2 und vor 2.25.6 wurde eine XML External Entity (XXE)-Schwachstelle identifiziert. Die Anwendung akzeptiert XML-Eingaben über einen spezifischen Endpunkt /geoserver/wms, Operation GetMap. Diese Eingabe wird jedoch nicht ausreichend bereinigt oder eingeschränkt, sodass ein Angreifer externe Entitäten innerhalb der XML-Anfrage definieren kann. Dieses Problem wurde in GeoServer 2.25.6, GeoServer 2.26.3 und GeoServer 2.27.0 behoben.
- CVE-2025-58034Hoch7.2
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
- CVE-2025-13223Hoch8.8
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-64446Kritisch9.8
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
- CVE-2025-62215Hoch7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-60710Hoch7.8
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
- CVE-2025-12480Kritisch9.1
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
- CVE-2025-64328Hoch7.2
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
This product uses the NVD API but is not endorsed or certified by the NVD.